EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingHard
A network security engineer is tasked with securing a wireless network that serves a public area, offering free Wi-Fi. The primary concern is protecting user privacy and preventing unauthorized access to client data, even if the network is open. Which security measure, when implemented on the access points, would provide individual encryption for each client session without requiring a pre-shared key or 802.1X authentication?
- AEnhanced Open (OWE)
- BWPA2-Enterprise with EAP-TLS
- CCaptive Portal with HTTPS
- DWPA3-Personal with SAE
Show answer & explanationAnswer & explanation
Correct answer: A. Enhanced Open (OWE)
Enhanced Open (OWE), as integrated into WPA3, provides opportunistic encryption for open Wi-Fi networks. It establishes a secure, individualized connection for each client without requiring a password or 802.1X, thus protecting traffic from passive sniffing while maintaining ease of access.
Why the other options are wrong
- B. WPA2-Enterprise with EAP-TLS requires complex certificate-based authentication, unsuitable for 'free Wi-Fi' without requiring credentials.
- C. A captive portal with HTTPS encrypts web traffic to the portal itself but does not provide end-to-end encryption for all Wi-Fi traffic without an underlying encryption protocol.
- D. WPA3-Personal with SAE requires a passphrase, which contradicts the 'open' nature of the public Wi-Fi.
Enhanced Open (OWE)
Enhanced Open (Opportunistic Wireless Encryption) is a Wi-Fi standard (integrated into WPA3) that provides individualized data encryption for open, public Wi-Fi networks. It secures communication between the client and the access point without requiring any pre-shared key or user authentication credentials.
- Provides opportunistic encryption for open Wi-Fi.
- Based on Diffie-Hellman key exchange for per-client session keys.
- Protects against passive eavesdropping on open networks.
Memory trick: OWE encrypts Open Wi-Fi, protecting every user's private flow.